X2Go Bug report logs - #459
PolicyKit authentication within apps often fails

version graph

Package: x2goserver; Maintainer for x2goserver is X2Go Developers <x2go-dev@lists.x2go.org>; Source for x2goserver is src:x2goserver.

Reported by: Michael DePaulo <mikedep333@gmail.com>

Date: Sun, 23 Mar 2014 16:30:02 UTC

Severity: normal

Found in version 4.0.1.13

Full log


Message #30 received at 459@bugs.x2go.org (full text, mbox, reply):

Received: (at 459) by bugs.x2go.org; 22 Aug 2014 21:33:41 +0000
From mike.gabriel@das-netzwerkteam.de  Fri Aug 22 23:33:40 2014
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00 autolearn=ham
	version=3.3.2
Received: from freya.das-netzwerkteam.de (freya.das-netzwerkteam.de [88.198.48.199])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTPS id 0BCD45DCA9
	for <459@bugs.x2go.org>; Fri, 22 Aug 2014 23:33:40 +0200 (CEST)
Received: from grimnir.das-netzwerkteam.de (grimnir.das-netzwerkteam.de [78.46.204.98])
	by freya.das-netzwerkteam.de (Postfix) with ESMTPS id 1C2141EFC;
	Fri, 22 Aug 2014 23:33:38 +0200 (CEST)
Received: from localhost (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTP id 67C723BBE6;
	Fri, 22 Aug 2014 23:33:39 +0200 (CEST)
X-Virus-Scanned: Debian amavisd-new at grimnir.das-netzwerkteam.de
Received: from grimnir.das-netzwerkteam.de ([127.0.0.1])
	by localhost (grimnir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id pe3KzOzd02EI; Fri, 22 Aug 2014 23:33:39 +0200 (CEST)
Received: from grimnir.das-netzwerkteam.de (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTPS id 26B083BBE5;
	Fri, 22 Aug 2014 23:33:39 +0200 (CEST)
Received: from p5B3B9266.dip0.t-ipconnect.de (p5B3B9266.dip0.t-ipconnect.de
 [91.59.146.102]) by mail.das-netzwerkteam.de (Horde Framework) with HTTP;
 Fri, 22 Aug 2014 21:33:39 +0000
Date: Fri, 22 Aug 2014 21:33:39 +0000
Message-ID: <20140822213339.Horde.0FGVLxzv6cUhXSZqYYA9vw1@mail.das-netzwerkteam.de>
From: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
To: Michael DePaulo <mikedep333@gmail.com>
Cc: 459@bugs.x2go.org
Subject: Re: [X2Go-Dev] Bug#459: PolicyKit authentication within apps often
 fails
References: <CAMKht8hxORsAXk32K=9ruNpF-PYWLUeyVvWqyeMsZhhb4uTWEQ@mail.gmail.com>
 <20140820093115.Horde.TjoWeWlTUbpPl3j2vDFNFw1@mail.das-netzwerkteam.de>
 <CAMKht8jYno1FNzfcmmo29SMHO4fx6e78Q+zOLnbky0Sv5qtE-A@mail.gmail.com>
 <CAMKht8gOyOr8_-DNtwXPXZfNuweG7EQ4NLc2Cnuv8BOPZCQ4Qg@mail.gmail.com>
In-Reply-To: <CAMKht8gOyOr8_-DNtwXPXZfNuweG7EQ4NLc2Cnuv8BOPZCQ4Qg@mail.gmail.com>
User-Agent: Internet Messaging Program (IMP) H5 (6.2.0)
Accept-Language: en,de
Organization: DAS-NETZWERKTEAM
X-Originating-IP: 91.59.146.102
X-Remote-Browser: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101
 Firefox/31.0 Iceweasel/31.0
Content-Type: multipart/signed; boundary="=_uTBSffVbA4jZeChpfMyH3g1";
 protocol="application/pgp-signature"; micalg=pgp-sha1
MIME-Version: 1.0
[Message part 1 (text/plain, inline)]
On  Mi 20 Aug 2014 16:14:34 CEST, Michael DePaulo wrote:

> On Wed, Aug 20, 2014 at 10:04 AM, Michael DePaulo  
> <mikedep333@gmail.com> wrote:
>> On Wed, Aug 20, 2014 at 5:31 AM, Mike Gabriel
>> <mike.gabriel@das-netzwerkteam.de> wrote:
>>> Hi Michael,
>>>
>>>
>>> On  So 23 Mär 2014 17:25:58 CET, Michael DePaulo wrote:
>>>
>>>> [...]
>>>
>>>
>>> I just fixed #458 by exporting $XAUTHORITY in x2goruncommand.
>>
>> Thank you :)
>>
>>> Do you have any clue what this issue may be related to? As I don't have any
>>> of the failing apps on Debian, I cannot reproduce your test results right
>>> away.
>>
>> 2 possible theories:
>> 1. We are not integrating with ConsoleKit and/or logind properly.
>> (Although it appears that our integration with logind is better, since
>> Fedora 20 works better than CentOS 6.)
>> 2. We have issues with the polcykit authentication windows not being
>> permitted to show up.
>>
> A 3rd possible theory:
> 3. PolicyKit policies are blocking certain actions from happening over
> any sort of remote session. PolicyKit refers to local sessions as
> "Active" and remote sessions as "Inactive".
> It appears that the X11RDP project has run into this problem:
> http://scarygliders.net/2012/06/20/a-brief-guide-to-policykit/
> http://scarygliders.net/category/policykit/
>

I stumbled over this the other day, when I was going through these  
polkit bugs, myself.

We don't want X2Go sessions to be "active=TRUE" and neither do we want  
them to be local.

Sessions are marked as active and local sessions if the user is really  
sitting in front of a machine. Those session will accept USB  
flashdrives when they are plugged into the workstation. We want that  
with local X.org sessions, but not in X2Go sessions.

Greets,
Mike
-- 

DAS-NETZWERKTEAM
mike gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148

GnuPG Key ID 0x25771B31
mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de

freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.xfb
[Message part 2 (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Thu Nov 21 15:11:24 2024; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.